Skip to content

build(deps): bump the minor-and-patch group with 9 updates - #61

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-fa3d184537
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-fa3d184537

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 9 updates:

Package From To
@modelcontextprotocol/server 2.1.0 2.2.0
@sentry/cloudflare 11.1.0 11.3.0
@cloudflare/workers-types 5.20260927.1 5.20261002.1
@modelcontextprotocol/client 2.1.0 2.2.0
@types/node 26.6.3 26.6.4
@vitest/coverage-v8 5.0.2 5.0.3
openai 7.23.0 7.27.0
vitest 5.0.2 5.0.3
wrangler 4.142.0 4.147.0

Updates @modelcontextprotocol/server from 2.1.0 to 2.2.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.2.0

Patch Changes

  • Updated dependencies [edd12e2]:
    • @​modelcontextprotocol/core@​2.2.0

@​modelcontextprotocol/server@​2.2.0

Patch Changes

  • #2885 9dd722f Thanks @​claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2778 e3fb9ed Thanks @​vjymisal0! - Fix a stack overflow in createMcpHandler when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required.

  • #2651 c55efa6 Thanks @​sushantkumar23! - createMcpHandler now ends a subscriptions/listen stream right after the acknowledgement when it honored none of the requested notification types, instead of holding the stream open with nothing to deliver. The client receives the acknowledgement and then the resultType: "complete" result. Streams that honor at least one type are unchanged.

  • Updated dependencies [edd12e2]:

    • @​modelcontextprotocol/core@​2.2.0
Commits
  • dd22ba2 Version Packages (#2849)
  • c55efa6 fix(server): close a listen stream that has honored nothing (#2651)
  • edd12e2 fix(client): deprecate omitting expectedIssuer and apply the SEP-2352 issuer ...
  • ef39308 fix(client): follow nextCursor until it is absent; stop on a repeated page (#...
  • 9dd722f fix(core): await the notification send so a failed send is never briefly unha...
  • e780e13 fix(client): preserve _meta on input_required results (#2862)
  • a4ae2f9 docs(client): correct the registerClient deprecation citation to spec PR #285...
  • efebf5b docs(client): correct token endpoint TLS citation (#2768)
  • d992df7 chore: remove CODEOWNERS patterns that match nothing on main (#2884)
  • c0f7aec fix(client): inline jose types in the CommonJS declaration file (#2883)
  • Additional commits viewable in compare view

Updates @sentry/cloudflare from 11.1.0 to 11.3.0

Release notes

Sourced from @​sentry/cloudflare's releases.

11.3.0

Important Changes

  • Remix 3 support (alpha, may break in minor releases)

    • feat(remix): Add Remix 3 browser SDK with a bundled client entry (#24802)
    • feat(remix): Add source map upload for Remix 3 (#24943)
    • feat(remix): Capture Remix 3 component render errors (#24873)
    • feat(remix): Complete Remix 3 server error handling (#24878)
    • feat(remix): Inject debug IDs through the Remix 3 asset server (#24761)
    • feat(remix): Run the orchestrion transform on Remix 3 browser modules (#24894)
  • feat(nextjs): Add cache_origin span links to use cache hit spans (#24821)

    A cache.get span for a "use cache" hit now carries a span link (sentry.link.type: 'cache_origin') to the cache.put span of the request that filled the cache entry, connecting the trace that reads a cached value to the trace that produced it.

  • fix(cloudflare): Don't treat DO constructor work as incoming RPC calls (#24829)

    Durable Object constructors now run in their own isolation scope. When work that the constructor starts, for example a blockConcurrencyWhile callback, calls a method of the instance, that call is no longer treated as an incoming RPC call, so an error the instance catches itself is no longer reported as unhandled. As a result, Sentry.setTag(), setUser() and setContext() in a constructor now apply only to that constructor work. They no longer reach later fetch, RPC or alarm invocations, because the scope they used to write to is shared by every Durable Object and handler in the isolate. Use initialScope for static data, and set per-instance data in each handler.

  • fix(effect)!: Change peerDependency to v4 and fix currentSpan (#24940)

    @sentry/effect now requires a stable Effect v4 release. Effect v4 beta and release candidate versions are no longer supported. @sentry/effect is in alpha, so this ships in a minor release.

Other Changes

  • feat(astro): Register astro route provider (#23792)
  • feat(cloudflare): Trace TypeSafe Jev calls in Workers AI as evaluate spans (#24833)
  • feat(core): Add route provider API for parameterized route resolution (#23551)
  • feat(deps): bump devalue from 5.9.2 to 5.9.4 (#24964)
  • feat(effect): Add opt-in for external span parents and isolate root spans (#23900)
  • feat(nextjs): Register nextjs route provider (#23552)
  • feat(nuxt): Register nuxt route provider (#23794)
  • feat(remix): Register remix route provider (#23791)
  • feat(vue): Register Vue route provider (#23793)
  • fix(bundler-plugins): Keep debug IDs on Vite source maps after the preload rewrite (#24920)
  • fix(bundler-plugins): Stabilize debug IDs for Rolldown and Vite 8 builds (#24919)
  • fix(cloudflare): Skip binding instrumentation work when spans are not sent (#24655)
  • fix(core, node, bun, deno): Align server span client address with event IP (#24767)
  • fix(hono): Return the existing client on repeated init in Bun and Deno (#24520)
  • fix(nitro): Capture errors only through the Nitro error hook (#24952)
  • fix(profiling-node): Send profile chunks with client.sendEnvelope (#24896)
  • fix(react-router): Avoid duplicating Vite config arrays (#24930)
  • fix(react-router): Resolve the Cloudflare entry in Workers and skip trace meta tags in prerendered pages (#24866)
  • fix(server-utils): Match the Anthropic stream helper header regardless of case (#24855)
  • fix(server-utils): Skip Fastify 4xx errors raised before the reply status is set (#24924)
  • fix(tanstackstart-react): Avoid duplicating Vite config arrays (#24929)

... (truncated)

Changelog

Sourced from @​sentry/cloudflare's changelog.

11.3.0

Important Changes

  • Remix 3 support (alpha, may break in minor releases)

    • feat(remix): Add Remix 3 browser SDK with a bundled client entry (#24802)
    • feat(remix): Add source map upload for Remix 3 (#24943)
    • feat(remix): Capture Remix 3 component render errors (#24873)
    • feat(remix): Complete Remix 3 server error handling (#24878)
    • feat(remix): Inject debug IDs through the Remix 3 asset server (#24761)
    • feat(remix): Run the orchestrion transform on Remix 3 browser modules (#24894)
  • feat(nextjs): Add cache_origin span links to use cache hit spans (#24821)

    A cache.get span for a "use cache" hit now carries a span link (sentry.link.type: 'cache_origin') to the cache.put span of the request that filled the cache entry, connecting the trace that reads a cached value to the trace that produced it.

  • fix(cloudflare): Don't treat DO constructor work as incoming RPC calls (#24829)

    Durable Object constructors now run in their own isolation scope. When work that the constructor starts, for example a blockConcurrencyWhile callback, calls a method of the instance, that call is no longer treated as an incoming RPC call, so an error the instance catches itself is no longer reported as unhandled. As a result, Sentry.setTag(), setUser() and setContext() in a constructor now apply only to that constructor work. They no longer reach later fetch, RPC or alarm invocations, because the scope they used to write to is shared by every Durable Object and handler in the isolate. Use initialScope for static data, and set per-instance data in each handler.

  • fix(effect)!: Change peerDependency to v4 and fix currentSpan (#24940)

    @sentry/effect now requires a stable Effect v4 release. Effect v4 beta and release candidate versions are no longer supported. @sentry/effect is in alpha, so this ships in a minor release.

Other Changes

  • feat(astro): Register astro route provider (#23792)
  • feat(cloudflare): Trace TypeSafe Jev calls in Workers AI as evaluate spans (#24833)
  • feat(core): Add route provider API for parameterized route resolution (#23551)
  • feat(deps): bump devalue from 5.9.2 to 5.9.4 (#24964)
  • feat(effect): Add opt-in for external span parents and isolate root spans (#23900)
  • feat(nextjs): Register nextjs route provider (#23552)
  • feat(nuxt): Register nuxt route provider (#23794)
  • feat(remix): Register remix route provider (#23791)
  • feat(vue): Register Vue route provider (#23793)
  • fix(bundler-plugins): Keep debug IDs on Vite source maps after the preload rewrite (#24920)
  • fix(bundler-plugins): Stabilize debug IDs for Rolldown and Vite 8 builds (#24919)
  • fix(cloudflare): Skip binding instrumentation work when spans are not sent (#24655)
  • fix(core, node, bun, deno): Align server span client address with event IP (#24767)
  • fix(hono): Return the existing client on repeated init in Bun and Deno (#24520)
  • fix(nitro): Capture errors only through the Nitro error hook (#24952)
  • fix(profiling-node): Send profile chunks with client.sendEnvelope (#24896)
  • fix(react-router): Avoid duplicating Vite config arrays (#24930)
  • fix(react-router): Resolve the Cloudflare entry in Workers and skip trace meta tags in prerendered pages (#24866)
  • fix(server-utils): Match the Anthropic stream helper header regardless of case (#24855)
  • fix(server-utils): Skip Fastify 4xx errors raised before the reply status is set (#24924)
  • fix(tanstackstart-react): Avoid duplicating Vite config arrays (#24929)

... (truncated)

Commits
  • 1e82c8f release: 11.3.0
  • 481c43c Merge pull request #24987 from getsentry/prepare-release/11.3.0
  • 1c7308d meta(changelog): Update changelog for 11.3.0
  • d880cf0 ref(core): Use SDK metadata constants from conventions (#24978)
  • 4b8c140 feat(remix): Add source map upload for Remix 3 (#24943)
  • ea5690e ref(core): Use profile ID constant from conventions (#24976)
  • ef90627 chore: Add external contributor to CHANGELOG.md (#24980)
  • 9c10641 fix(server-utils): Skip Fastify 4xx errors raised before the reply status is ...
  • c65ec66 ref(core): Use HTTP method constant from conventions (#24977)
  • 9e77e9d ref(core): Use user attribute constants from conventions (#24974)
  • Additional commits viewable in compare view

Updates @cloudflare/workers-types from 5.20260927.1 to 5.20261002.1

Commits

Updates @modelcontextprotocol/client from 2.1.0 to 2.2.0

Release notes

Sourced from @​modelcontextprotocol/client's releases.

@​modelcontextprotocol/client@​2.2.0

Minor Changes

  • #2887 edd12e2 Thanks @​maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

Patch Changes

  • #2885 9dd722f Thanks @​claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2883 c0f7aec Thanks @​claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0: dist/index.d.cts imported types from jose, which is ESM-only, so tsc with module: node16/node18 and skipLibCheck: false failed with TS1479. The two jose types used by the DPoP API (CryptoKey, JWK) are now inlined into the declaration files. No runtime change.

  • #2768 efebf5b Thanks @​web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.

  • #2729 a4ae2f9 Thanks @​claude! - Correct the registerClient @deprecated notice: Dynamic Client Registration was deprecated by spec PR modelcontextprotocol#2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that the client_id_metadata_document_supported gating lives in the built-in auth() flow — registerClient called directly always sends the registration request. Documentation only; no runtime behavior change.

  • #2862 e780e13 Thanks @​SyedTashfin! - Preserve _meta on input_required results. The 2026-07-28 decode seam rebuilt the payload from inputRequests and requestState only, so result-level metadata a server sent on an input_required result (including io.modelcontextprotocol/serverInfo) was dropped before an allowInputRequired: true caller could see it. Result._meta is a result-level field, so input_required carries it exactly like any other result.

  • #2886 ef39308 Thanks @​claude! - listTools(), listPrompts(), listResources() and listResourceTemplates() called without a cursor now follow nextCursor until the server stops sending one, instead of stopping silently with a short list when a cursor repeats; a page that has the same items and the same nextCursor as the page before it ends the walk and is not added twice, and listMaxPages still caps the walk.

  • #2642 cfa09db Thanks @​claude! - Fix Client.listen() rejections escaping as process-level unhandled rejections. The internal opening promise could reject (ack timeout, transport close, server cancel, caller abort) while listen() was still serially awaiting transport.send(...), so no rejection handler was attached yet — the rejection surfaced as an unhandledRejection that caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on 'drain') left listen() suspended forever even though the ack timer had already fired. listen() now suspends on the opening state machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes.

  • #2597 7f7a94c Thanks @​arimu1! - Treat hostnames ending in .localhost as loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself: *.localhost reaches the local machine only if the system resolver follows RFC 6761.

  • Updated dependencies [edd12e2]:

    • @​modelcontextprotocol/core@​2.2.0
Commits
  • dd22ba2 Version Packages (#2849)
  • c55efa6 fix(server): close a listen stream that has honored nothing (#2651)
  • edd12e2 fix(client): deprecate omitting expectedIssuer and apply the SEP-2352 issuer ...
  • ef39308 fix(client): follow nextCursor until it is absent; stop on a repeated page (#...
  • 9dd722f fix(core): await the notification send so a failed send is never briefly unha...
  • e780e13 fix(client): preserve _meta on input_required results (#2862)
  • a4ae2f9 docs(client): correct the registerClient deprecation citation to spec PR #285...
  • efebf5b docs(client): correct token endpoint TLS citation (#2768)
  • d992df7 chore: remove CODEOWNERS patterns that match nothing on main (#2884)
  • c0f7aec fix(client): inline jose types in the CommonJS declaration file (#2883)
  • Additional commits viewable in compare view

Updates @types/node from 26.6.3 to 26.6.4

Commits

Updates @vitest/coverage-v8 from 5.0.2 to 5.0.3

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates openai from 7.23.0 to 7.27.0

Release notes

Sourced from openai's releases.

v7.27.0

7.27.0 (2026-10-01)

Features

  • agents: prepare hosted files and download result artifacts (#2855) (7b5a9e0)

v7.26.0

7.26.0 (2026-10-01)

Features

  • collect final output from beta Agents streams (#2850) (71d2412)
  • agents: [1/n] parse typed output from agent streams (#2853) (95b197b)
  • api: Add agent session trace listing (#2845) (c6dd4c7)
  • beta: bind typed application functions to Agents tools (#2852) (6198ba0)

Bug Fixes

  • api: allow original image detail in Chat Completions (#2851) (a3c1af5)
  • api: correct the eval run cancellation endpoint (#2847) (2f77415)
  • deps-dev: bump @​swc/core from 1.16.1 to 1.16.2 (#2827) (ff26e64)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/browser-direct-import (#2823) (53f8877)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/ts-browser-webpack (#2830) (2ac0cf2)
  • deps-dev: bump webpack from 5.110.3 to 5.111.1 in /ecosystem-tests/ts-browser-webpack (#2828) (89de47a)
  • deps-dev: bump wrangler from 4.131.1 to 4.135.0 in /ecosystem-tests/cloudflare-worker (#2824) (8c2e159)
  • deps-dev: update Vercel CLI to remove legacy proxy dependencies (#2835) (94395e8)
  • deps-dev: upgrade Vitest and migrate performance benchmarks (#2831) (a1421b1)
  • deps: bump @​azure/identity from 4.13.2 to 4.13.3 (#2825) (bfa2dec)
  • deps: bump dotenv from 17.4.2 to 18.0.1 (#2822) (6d0a62c)
  • deps: bump zod from 4.5.4 to 4.6.5 (#2829) (d2e9a06)
  • responses: refresh credentials on WebSocket reconnects (#2856) (0afb3da)
  • responses: reserve lane IDs across WebSocket session replacements (#2842) (8b5e176)

Chores

  • api: retain WebRTC Live session transport types (#2846) (9798c93)

v7.25.0

7.25.0 (2026-09-29)

Features

... (truncated)

Changelog

Sourced from openai's changelog.

7.27.0 (2026-10-01)

Features

  • agents: prepare hosted files and download result artifacts (#2855) (7b5a9e0)

7.26.0 (2026-10-01)

Features

  • collect final output from beta Agents streams (#2850) (71d2412)
  • agents: [1/n] parse typed output from agent streams (#2853) (95b197b)
  • api: Add agent session trace listing (#2845) (c6dd4c7)
  • beta: bind typed application functions to Agents tools (#2852) (6198ba0)

Bug Fixes

  • api: allow original image detail in Chat Completions (#2851) (a3c1af5)
  • api: correct the eval run cancellation endpoint (#2847) (2f77415)
  • deps-dev: bump @​swc/core from 1.16.1 to 1.16.2 (#2827) (ff26e64)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/browser-direct-import (#2823) (53f8877)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/ts-browser-webpack (#2830) (2ac0cf2)
  • deps-dev: bump webpack from 5.110.3 to 5.111.1 in /ecosystem-tests/ts-browser-webpack (#2828) (89de47a)
  • deps-dev: bump wrangler from 4.131.1 to 4.135.0 in /ecosystem-tests/cloudflare-worker (#2824) (8c2e159)
  • deps-dev: update Vercel CLI to remove legacy proxy dependencies (#2835) (94395e8)
  • deps-dev: upgrade Vitest and migrate performance benchmarks (#2831) (a1421b1)
  • deps: bump @​azure/identity from 4.13.2 to 4.13.3 (#2825) (bfa2dec)
  • deps: bump dotenv from 17.4.2 to 18.0.1 (#2822) (6d0a62c)
  • deps: bump zod from 4.5.4 to 4.6.5 (#2829) (d2e9a06)
  • responses: refresh credentials on WebSocket reconnects (#2856) (0afb3da)
  • responses: reserve lane IDs across WebSocket session replacements (#2842) (8b5e176)

Chores

  • api: retain WebRTC Live session transport types (#2846) (9798c93)

7.25.0 (2026-09-29)

Features

7.24.0 (2026-09-29)

... (truncated)

Commits
  • e39bd99 release: 7.27.0 (#2857)
  • 7b5a9e0 feat(agents): prepare hosted files and download result artifacts (#2855)
  • a06c456 release: 7.26.0 (#2844)
  • 0afb3da fix(responses): refresh credentials on WebSocket reconnects (#2856)
  • 95b197b feat(agents): [1/n] parse typed output from agent streams (#2853)
  • 6198ba0 feat(beta): bind typed application functions to Agents tools (#2852)
  • 71d2412 feat: collect final output from beta Agents streams (#2850)
  • a1421b1 fix(deps-dev): upgrade Vitest and migrate performance benchmarks (#2831)
  • a3c1af5 fix(api): allow original image detail in Chat Completions (#2851)
  • 94395e8 fix(deps-dev): update Vercel CLI to remove legacy proxy dependencies (#2835)
  • Additional commits viewable in compare view

Updates vitest from 5.0.2 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

Bumps the minor-and-patch group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.1.0` | `2.2.0` |
| [@sentry/cloudflare](https://github.com/getsentry/sentry-javascript) | `11.1.0` | `11.3.0` |
| [@cloudflare/workers-types](https://github.com/cloudflare/workerd) | `5.20260927.1` | `5.20261002.1` |
| [@modelcontextprotocol/client](https://github.com/modelcontextprotocol/typescript-sdk) | `2.1.0` | `2.2.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.2` | `5.0.3` |
| [openai](https://github.com/openai/openai-node) | `7.23.0` | `7.27.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.2` | `5.0.3` |
| [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `4.142.0` | `4.147.0` |


Updates `@modelcontextprotocol/server` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.1.0...@modelcontextprotocol/server@2.2.0)

Updates `@sentry/cloudflare` from 11.1.0 to 11.3.0
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@11.1.0...11.3.0)

Updates `@cloudflare/workers-types` from 5.20260927.1 to 5.20261002.1
- [Release notes](https://github.com/cloudflare/workerd/releases)
- [Changelog](https://github.com/cloudflare/workerd/blob/main/RELEASE.md)
- [Commits](https://github.com/cloudflare/workerd/commits)

Updates `@modelcontextprotocol/client` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/client@2.1.0...@modelcontextprotocol/client@2.2.0)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `openai` from 7.23.0 to 7.27.0
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/main/CHANGELOG.md)
- [Commits](openai/openai-node@v7.23.0...v7.27.0)

Updates `vitest` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `wrangler` from 4.142.0 to 4.147.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.147.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@sentry/cloudflare"
  dependency-version: 11.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@cloudflare/workers-types"
  dependency-version: 5.20261002.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/client"
  dependency-version: 2.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: openai
  dependency-version: 7.27.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: wrangler
  dependency-version: 4.147.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants